RSS   Vulnerabilities for 'Phpchain'   RSS

2007-05-14
 
CVE-2007-2670

 

 
PHPChain 1.0 and earlier allows remote attackers to obtain the installation path via invalid values of the catid parameter to (1) settings.php or (2) cat.php, as demonstrated by XSS manipulations.

 
 
CVE-2007-2669

 

 
Multiple cross-site scripting (XSS) vulnerabilities in PHPChain 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the catid parameter to (1) settings.php or (2) cat.php. NOTE: certain parameter values also trigger path disclosure.

 

 >>> Vendor: Globalmegacorp 2 Products
Dvddb
Phpchain


Copyright 2024, cxsecurity.com

 

Back to Top